Critical Infrastructure Under Siege: Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
A sophisticated ransomware-as-a-service (RaaS) operation is wreaking havoc on critical infrastructure and government organizations worldwide. The Gunra gang, which emerged in 2025, has been exploiting known vulnerabilities in firewall and VPN appliances to gain initial access and evade multifactor authentication (MFA). This brazen tactic has allowed the group to successfully target a range of sectors, including healthcare, finance, and transportation.
According to a joint cybersecurity alert issued by US and South Korean government agencies, Gunra’s ransomware is based on the leaked source code of the now-defunct Conti gang. Initially targeting Windows environments, the group later developed a Linux variant and expanded its operations this year through a structured RaaS affiliate program advertised on Dark Web forums. This has enabled financially motivated cybercriminals to join forces with the gang.
One of the most significant concerns surrounding Gunra’s tactics is their exploitation of N-day vulnerabilities in Fortinet products. Specifically, the FBI observed the group using two critical authentication bypass flaws: CVE-2024-55591 and CVE-2025-24472. The first vulnerability allows an attacker to achieve “super admin” privileges in Fortinet appliances, while the second enables authentication bypass in FortiOS and FortiProxy software.
The impact of these vulnerabilities is far-reaching. Not only have they been heavily targeted by ransomware actors since their disclosure, but it appears that many organizations have yet to patch them. This has left critical infrastructure targets vulnerable to attack. In one notable example, Gunra affiliates took control of an SSL-VPN appliance and used traffic control functionality to collect employee credentials and session information for a corporate virtual desktop infrastructure (VDI) portal.
The group’s tactics are particularly insidious, as they often involve bypassing MFA protection by modifying authentication processing files on the corporate VDI authentication portal server. This allows successful authentication when a specific one-time password (OTP) value is entered, effectively enabling continuous bypass of MFA. Furthermore, Gunra affiliates have been known to delete backups and archived data stored at both primary and disaster recovery centers before and after deploying ransomware.
The takeaways from this situation are clear: organizations must prioritize patching Fortinet vulnerabilities, monitor for suspicious activity around identity and access management infrastructure, and maintain robust backup and disaster recovery procedures. By taking proactive steps to secure their networks, critical infrastructure targets can reduce the risk of falling prey to Gunra’s tactics. As the cybersecurity landscape continues to evolve, it is essential that organizations stay vigilant and adapt to emerging threats in order to protect themselves against these types of attacks.
Source: Dark Reading — 2026-08-11